■■■■□ Cloudflare Zero-Day Vulnerability Enables Any Host Access Bypassing Protections. Cloudflare Zero-Day Vulnerability Enables Any Host Access Bypassing Protections
All posts in Uncategorized
January 20, 2026 at 11:28PM
■□□□□ Billion-Dollar Bait & Switch: Exploiting a Race Condition in Blockchain Infrastructure. https://mavlevin.com/2026/01/18/flashbots-mev-relay-race-condition-vulnerability
January 19, 2026 at 10:34PM
■■■■□ Security automation with n8n ideas: 100+ Red/Blue/AppSec workflows, integrations, and ready-to-run playbooks. https://github.com/0xSojalSec/n8n-Red-Blue-AppSec-workflows
January 19, 2026 at 09:42AM
■■□□□ Sirius is an open-source comprehensive vulnerability scanner that leverages community-driven security intelligence and automated penetration testing capabilities. https://github.com/SiriusScan/Sirius
January 18, 2026 at 09:00PM
4️⃣ The AWS hack, a supply chain ⛓️ attack taking over AWS JavaScript library. Am interesting thread! https://x.com/i/status/2011842613389726109
January 17, 2026 at 09:43PM
https://state-of-iranblackout.whisper.security/
January 17, 2026 at 09:33PM
⭐️InvisibleJS: A CLI tool to convert JavaScript into an invisible, executable payload using Zero-Width encoding. https://github.com/oscarmine/InvisibleJS.git
January 17, 2026 at 09:52AM
■■□□□ United States: A Chinese-linked cyberespionage group targeted U.S. government and policy-related officials with Venezuela-themed phishing emails in the days after the U.S. operation to topple Venezuelan President Nicolas Maduro, cybersecurity researchers said Thursday. https://www.reuters.com/business/media-telecom/chinese-linked-hackers-target-us-entities-with-venezuelan-themed-malware-2026-01-15/
January 17, 2026 at 09:51AM
■■■■■ $312,500 worth of stored/reflected XSS vulnerabilities in Meta’s Conversions API Gateway allowed Javascript code to run on any Facebook domain and millions of third-party websites. The flaw enabled zero-click Facebook account takeover and more: https://ysamm.com/uncategorized/2025/01/13/capig-xss.html
January 17, 2026 at 09:50AM
■■■■□ Instagram account takeover via Meta Pixel script abuse (Bug bounty – $32,500) by Youssef Sammouda. https://ysamm.com/uncategorized/2026/01/16/leaking-fbevents-ato.html
